Posted at: 6 March
Senior Security Engineer
Company
Bugcrowd
Bugcrowd is a San Francisco-based B2B crowdsourced security platform specializing in bug bounty programs and penetration testing, serving various industries globally.
Remote Hiring Policy:
Bugcrowd supports remote work and hires globally, with team members located in various regions including the United States, Australia, and the UK.
Job Type
Full-time
Allowed Applicant Locations
Armenia, Worldwide
Job Description
Job Summary The Senior Security Engineer’s role is to aid the organizational security efforts of Bugcrowd, while proactively improving our security posture. As the last line of defense for one of the largest crowdsourced security platforms, you will be challenged regularly! Accordingly, we require a motivated team who are willing to push their own boundaries and step out of their comfort zones, while being supported by Bugcrowd and the director of Cybersecurity. The Senior Security Engineer will receive mentoring from the team, while providing mentoring to others, and you will be responsible for managing your individual engineering workload. This role also requires excellent communication skills as the cybersecurity department liaises with all other departments within the company.
Essential Duties and Responsibilities
Security Architecture and Application Security - Working with developers to uplift the current security controls and architecting solutions
Tool Creation - Creating tools used internally for securing the company, majorly in Python and Golang
Operations / Incident Response - Aiding with the process of Incident Response, and security operational activities when required
Risk Management - Assessing the risk behind security issues, and tracking core metrics
Pentesting - Performing security assessments of Bugcrowd assets (and vendors)
Quality Improvement - Contributing to the continual improvement of the Cybersecurity team’s policies and standards of practice
Experience Required
5+ experience in a similar role or its equivalent.
Familiarity with application security testing techniques (can perform a security assessment and code review should they be given a product, identifying weaknesses, ability to document findings, exploit development experience is a bonus)
Knowledge of OWASP Top 10 and common security vulnerabilities of modern web apps
Knowledge of Incident Response and operating systems as this role requires responding to incidents within the specified timezone
Knowledge of threat intelligence
Ability to understand a vulnerability and work with developers to patch it
Knowledge and proficiency with coding in at least two of: Python, JavaScript, Ruby, Golang
Great communicator who is comfortable communicating across multiple teams
Self motivated, autonomous and organized - must be able to operate from a calendar, be punctual, and being able to manage timelines of projects/tasks for self and others
Cloud experience (AWS preferred)
Understanding of Identity and Access Management (IAM)
Ability to proactively find solutions ie. figure things out for themselves (look at configurations, learn what they mean, document potential solutions to solve the problems)
Has the ability to be self-sufficient
Has some prior red teaming knowledge
Familiarity with git and pull requests is a must
Familiarity with a ticketing system / issue tracking system is a must (e.g: Notion and Jira)
Preferred Bachelors Degree in Computer Science, MIS or equivalent experience
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.